According to PHPinfo, the version of Mod_ssl in use is "2.2.21". Since the Mod_ssl crew never mentions this exact version number, but it does exactly match the Apache version, i assume that the version reported is not entirely accurate.
I need to to confirm what version of Mod_ssl is included, then if necessary upgrade to the version specified below.
Apache/2.2.21 (Win32) mod_ssl/2.2.21 OpenSSL/1.0.0e PHP/5.3.8 mod_perl/2.0.4 Perl/v5.10.1
Vulnerability Solution:
Download and apply the upgrade from: http://www.modssl.org/
Upgrade to version 2.8.19 of mod_ssl, which was released on July 16th, 2004.
The source code for this release can be downloaded from mod_ssl's website. To obtain binaries for your platform, please visit your vendor's site. Please note that some operating system vendors choose to apply the most recent mod_ssl security patches to their distributions without changing the package version to the most recent mod_ssl version number.